ATT&CKReferencesSecureWorks August 2019

SecureWorks August 2019

SecureWorks 2019, August 27 LYCEUM Takes Center Stage in Middle East Campaign Retrieved. 2019/11/19

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples26

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareDanBot

DanBot can upload files from compromised hosts.

T1010
Application Window Discovery
GroupHEXANE

HEXANE has used a PowerShell-based keylogging tool to capture the window title.

T1021.001
Remote Desktop Protocol
GroupHEXANE

HEXANE has used remote desktop sessions for lateral movement.

T1027.013
Encrypted/Encoded File
MalwareDanBot

DanBot can Base64 encode its payload.

T1053.005
Scheduled Task
MalwareDanBot

DanBot can use a scheduled task for installation.

T1056.001
Keylogging
GroupHEXANE

HEXANE has used a PowerShell-based keylogger named `kl.ps1`.

T1059.001
PowerShell
GroupHEXANE

HEXANE has used PowerShell-based tools and scripts for discovery and collection on compromised hosts.

T1059.003
Windows Command Shell
MalwareDanBot

DanBot has the ability to execute arbitrary commands via `cmd.exe`.

T1059.005
Visual Basic
MalwareDanBot

DanBot can use a VBA macro embedded in an Excel file to drop the payload.

T1071.001
Web Protocols
MalwareDanBot

DanBot can use HTTP in C2 communication.

T1071.004
DNS
MalwareDanBot

DanBot can use use IPv4 A records and IPv6 AAAA DNS records in C2 communications.

T1087.002
Domain Account
ToolEmpire

Empire can acquire local and domain user account information.

T1105
Ingress Tool Transfer
MalwareDanBot

DanBot can download additional files to a targeted system.

T1110
Brute Force
GroupHEXANE

HEXANE has used brute force attacks to compromise valid credentials.

T1110.003
Password Spraying
GroupHEXANE

HEXANE has used password spraying attacks to obtain valid credentials.

T1140
Deobfuscate/Decode Files or Information
MalwareDanBot

DanBot can use a VBA macro to decode its payload prior to installation and execution.

T1204.002
Malicious File
GroupHEXANE

HEXANE has relied on victim's executing malicious file attachments delivered via email or embedded within actor-controlled websites to deliver malware.

T1204.002
Malicious File
MalwareDanBot

DanBot has relied on victims' opening a malicious file for initial execution.

T1534
Internal Spearphishing
GroupHEXANE

HEXANE has conducted internal spearphishing attacks against executives, HR, and IT personnel to gain information and access.

T1555
Credentials from Password Stores
ToolPoshC2

PoshC2 can decrypt passwords stored in the RDCMan configuration file.

T1566.001
Spearphishing Attachment
MalwareDanBot

DanBot has been distributed within a malicious Excel attachment via spearphishing emails.

T1583.001
Domains
GroupHEXANE

HEXANE has registered and operated domains for campaigns, often using a security or web technology theme or impersonating the targeted organization.

T1586.002
Email Accounts
GroupHEXANE

HEXANE has used compromised accounts to send spearphishing emails.

T1588.002
Tool
GroupHEXANE

HEXANE has acquired, and sometimes customized, open source tools such as Mimikatz, Empire, VNC remote access software, and DIG.net.

T1589.002
Email Addresses
GroupHEXANE

HEXANE has targeted executives, human resources staff, and IT personnel for spearphishing.

T1591.004
Identify Roles
GroupHEXANE

HEXANE has identified executives, HR, and IT staff at victim organizations for further targeting.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.